Configuring Tacacs+ Authorization - Cisco WS-X6066-SLB-APC - Content Switching Module Software Manual

Catalyst 6000 series software configuration guide
Hide thumbs Also See for WS-X6066-SLB-APC - Content Switching Module:
Table of Contents

Advertisement

Configuring Authorization

Configuring TACACS+ Authorization

These sections describe how to configure TACACS+ authorization on the switch.
Enabling TACACS+ Authorization
To enable TACACS+ authorization on the switch, perform this task in privileged mode:
Task
Step 1
Enable authorization for normal mode. Enter the
console or telnet keyword if you want to enable
authorization only for console port or Telnet
connection attempts. Enter the both keyword to
enable authorization for both console port and
Telnet connection attempts.
Step 2
Enable authorization for enable mode. Enter the
console or telnet keyword if you want to enable
authorization only for console port or Telnet
connection attempts. Enter the both keyword to
enable authorization for both console port and
Telnet connection attempts.
Step 3
Enable authorization of configuration commands.
Enter the console or telnet keyword if you want to
enable authorization only for console port or
Telnet connection attempts. Enter the both
keyword to enable authorization for both console
port and Telnet connection attempts.
Step 4
Verify the TACACS+ authorization configuration. show authorization
This example shows how to enable TACACS+ EXEC mode authorization for both console and Telnet
connections. Authorization is configured with the tacacs+ option. The fallback option is deny:
Console> (enable) set authorization exec enable tacacs+ deny both
Successfully enabled enable authorization.
Console>
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
21-52
You must specify the mode, option, fallback option, and connection type when enabling
authorization.
Configure RADIUS and TACACS+ servers before enabling authorization. See the
TACACS+ Servers" section on page 21-17
page 21-24
for more information on server setup.
Configure RADIUS and TACACS+ keys to encrypt protocol packets before enabling authorization.
See the
"Specifying the TACACS+ Key" section on page 21-19
Key" section on page 21-24
Enabling TACACS+ Authorization, page 21-52
Disabling TACACS+ Authorization, page 21-53
or the
"Specifying RADIUS Servers" section on
for more information on the key setup.
Command
set authorization exec enable
{option}{fallbackoption} [console | telnet | both]
set authorization enable enable {option}
{fallbackoption} [console | telnet | both]
set authorization commands enable {config |
all} {option}{fallbackoption} [console | telnet |
both]
Chapter 21
Configuring Switch Access Using AAA
or the
"Specifying the RADIUS
"Specifying
78-13315-02

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents